TRAFEED

Credit Checks vs. Export Control Due Diligence: Where to Draw the Line on Vetting Export Partners

Published2026-07-19Ryuta Hamamoto

A financial credit check on an export partner and export control due diligence are both "counterparty screening," yet their purpose and the items they examine are entirely different. This article draws the line between credit checks, which assess payment-collection risk, and export control due diligence — classification plus end-user and end-use verification — which assesses the risk of violating Japan's Foreign Exchange and Foreign Trade Act, based on primary sources from METI, JETRO, and e-Gov.

Credit Checks vs. Export Control Due Diligence: Where to Draw the Line on Vetting Export Partners
シェア

Hello, this is Ryuta Hamamoto from TIMEWELL.

Before signing with a new overseas partner, you order a report from a credit agency. The financials look healthy, the rating is decent. "This company looks fine," you conclude, and the deal clears internal approval. It is a scene I see constantly on the export floor. But there is a trap here. What a credit check lets you conclude "safe to deal with" covers exactly one thing: whether they will pay you on time. If the counterparty happens to be a sanctioned entity, or an end user with a risk of military diversion, the credit rating will tell you nothing about it.

Vetting an export partner actually involves two investigations of entirely different character. One is the financial credit check. The other is export control due diligence — classification plus transaction screening. Confuse the two, and you can end up in the worst case of all: "credit approved, then sanctioned for a Foreign Exchange and Foreign Trade Act violation." If your company is an exporter, I recommend starting with the free export compliance check to see whether there are any gaps in how you vet your partners. In this article, I will lay out how the two sets of investigation items differ, and where the line should be drawn, based on primary sources.

The Bottom Line First: Credit Checks and Export Control DD Are Genuinely Different Things

Let me give you the conclusion up front. A financial credit check and export control due diligence may look like the same task of "investigating a counterparty," but the question each one poses is fundamentally different. The former asks: "Can this company pay, and is it at risk of going under?" The latter asks: "Is it legally sound to export this, for this purpose, to this party?" Different questions naturally mean different items to examine, different sources to consult, and different departments in charge.

Put side by side in a single table, the difference becomes clear.

Perspective Financial credit check Export control due diligence
Main purpose Assess payment-collection risk (the partner's ability to pay) Assess legal-violation risk (breaching the Foreign Exchange and Foreign Trade Act or sanctions)
Question posed Can this company pay, and will it avoid bankruptcy? Is it legally sound to export to this party for this use?
Main items examined Track record, capital, scale, profit and loss, cash position, management, corporate vitality (rating) Classification, end-user verification, end-use verification, sanctions-list screening, UBO, military links
Sources consulted Financial statements, corporate registry, credit-agency ratings Foreign End User List, U.S. Entity List, OFAC SDN and other sanctions lists
Who performs it Credit management team, credit agencies (e.g., Teikoku Databank) Export control team (plus sanctions-screening tools)
Basis / framework Trade credit management (contracts, voluntary risk management) FEFTA Art. 25(1) and 48(1), the compliance-standards ordinance, Item 16 of Appended Table 1 of the Export Order
If you neglect it Bad debt, uncollectible receivables Penalties, export bans, reputational damage, exposure to U.S. reexport controls

Compare the bottom row of that table. Neglect one side and you get bad debt — a money problem. Neglect the other and you get administrative sanctions or criminal penalties, plus exposure to U.S. reexport controls — problems that can threaten the survival of the business. Accidents happen precisely because companies try to settle two risks of completely different nature with a single investigation. My view is that these two should be designed as separate processes from the outset.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

What a Financial Credit Check Sees: "Can They Pay?"

The purpose of a financial credit check is straightforward. After you ship goods to a counterparty, can you reliably collect payment? How great is the risk that the partner becomes insolvent or goes bankrupt and leaves your receivables uncollectible? Credit management is about weighing this to decide whether to trade and how much credit to extend (the ceiling on open-account sales).

In Japan, the two large agencies, Teikoku Databank and Tokyo Shoko Research, are said to hold the bulk of the corporate credit-check market. The reports both produce are built from two kinds of information combined: quantitative and qualitative1. Quantitative information is data that can be expressed in numbers, such as figures from financial statements and registry records. Qualitative information is the harder-to-quantify factors — the company's position within its industry, the management team's capability and technical strength, the outlook for the business — assessed by an investigator. The report integrates both and assigns a "rating" score based on the agency's proprietary criteria. The higher the rating, the stronger the reading on ability to pay and business stability.

The point to grasp here is that this rating answers only the question of "ability to pay." A company with a long track record, healthy financials, and a well-regarded management team earns a high rating. That tells you it is "a company likely to pay you." But whether that company is designated on a sanctions list, who ultimately controls it behind the scenes, or whether its products might be diverted to military use — on these questions, the credit check says not a word. That is only natural, because the purpose is different. A credit rating was never built to measure export control risk.

What Export Control Due Diligence Sees: "Will This Break the Law?"

The other side, export control due diligence, is not about payment; it is about the law. Japanese exporters bear an obligation under the Foreign Exchange and Foreign Trade Act (FEFTA, Act No. 228 of 1949) to confirm that the goods or technology they intend to export do not run afoul of controls2. This confirmation has a broadly two-tier structure. The ground floor is classification; the second floor is transaction screening34.

The ground floor, classification, is the work of examining the item itself. You determine whether the goods or technology you intend to export matches the specifications defined as controlled under the law. The targets are the items known as list controls: weapons themselves, high-performance machine tools, certain semiconductor manufacturing equipment, and the like. If an item is classified as controlled (a "hit"), a license from the Minister of Economy, Trade and Industry is required in principle.

The second floor, transaction screening, examines not the item but who will use it and for what purpose. What matters here is the supplementary export controls (catch-all controls). This is the mechanism whereby, even for an item not caught by list controls, a license becomes necessary if there is a risk it will be used to develop weapons of mass destruction or conventional weapons. The basis lies in Article 25(1) of FEFTA (transactions in specified technology) and Article 48(1) (export of goods to specified regions), and the covered items are set out in Item 16 of Appended Table 1 of the Export Trade Control Order (Cabinet Order No. 378 of 1949)5. The applicable regions are those outside Group A (the former "white countries").

Supplementary export controls operate on two tracks: the objective condition and the inform requirement67. The objective condition further splits into a use requirement and an end-user requirement. The use requirement asks "is there a risk this item will be used to develop weapons of mass destruction and the like?" The end-user requirement asks "is the counterparty (importer or end user) developing weapons of mass destruction and the like, or is it an entity listed on the Foreign End User List?" The inform requirement means a license becomes necessary when METI issues a notice ("inform") instructing you to obtain one. These supplementary export controls are revised on an ongoing basis; most recently, amended provisions took effect on October 9, 20258.

These verifications are required as a matter of institutional design, not as an aspirational target. The Ordinance Establishing Compliance Standards for Exporters (METI Ordinance No. 60 of 2009), based on Article 55-10 of FEFTA, requires exporters to establish and carry out these verification procedures9. The ordinance is structured so that Article 1 sets the standard common to all exporters and Article 2 imposes additional standards on exporters of specified critical goods. Article 2 calls for procedures to verify end users and end uses, and procedures to raise the reliability of information obtained from sources other than the end user. In short, transaction screening should run as an internal procedure, not on the goodwill of the person in charge. I have laid out how to actually run transaction screening in more detail in the practice of counterparty screening (end-user verification).

A Credit Rating Cannot Reveal Sanctions, Ultimate Ownership, or Military End Use

This is the line I most want to draw in this article. However high a credit rating may be, it does not reveal export control risk. Conversely, however carefully you run export control checks, you cannot learn a counterparty's ability to pay. The two shine light on entirely different surfaces.

Let me list a few common misconceptions. First, the assumption that "a high credit rating equals a safe counterparty." This is dangerous. A rating indicates ability to pay; it does not reflect sanctions exposure or military-use risk. Even a financially excellent company may well have a sanctioned parent behind it. I have laid out how to read sanctions lists themselves in the complete guide to sanctions lists, but the essence is this: a credit yardstick cannot make the sanctions call.

Next, the misconception that "if we do an anti-social-forces check, that also covers export controls." An anti-social-forces check (in the lineage of organized-crime exclusion ordinances and the Act on Prevention of Transfer of Criminal Proceeds) and export control due diligence (in the FEFTA lineage) rest on different laws and target different risks. An anti-social-forces check looks at whether the counterparty is an anti-social force; it does not look at concerns over weapons-of-mass-destruction development or sanctions-list exposure. I explain the difference in an introduction to KYB and anti-social-forces checks.

Another deep-seated one concerns ultimate beneficial ownership (UBO). Some people reason, "the credit report lists the controlling shareholder, so UBO is already screened." But the controlling-shareholder information in a credit check and the UBO identification and list screening you perform for export control or sanctions purposes differ in both purpose and precision. What export control asks is: tracing through indirect holdings and capital relationships that span multiple countries, who ultimately holds control, and whether that person or organization is a sanctioned party or an end user of concern. I have set out the fundamentals of this thinking in what an ultimate beneficial owner (UBO) is. The controlling-shareholder information in a credit check can be a starting point for that, but it is no substitute for the screening itself.

A word on the Foreign End User List as well. This list is not an embargo list that says "no exports to listed entities"10. It merely identifies entities that "require verification" when transacting. Even for a shipment addressed to a listed entity, you confirm the nature of the goods or technology, the end use, the end user, the category of concern, and the transaction pattern, and then decide whether a license application is needed. This list was revised in an announcement on September 29, 2025; after the revision it lists 835 entities across 15 countries and regions10. That the number keeps climbing tells you the pool of parties requiring verification is expanding worldwide.

Running It in Practice: Splitting "Counterparty Screening" Between Credit and Export Control Teams

So how should this run in practice? My view is simple: take the single phrase "counterparty screening" and, from the very start, assign it to two owners. The credit management team handles ability to pay (payment-collection risk); the export control team handles legal-violation risk (FEFTA and sanctions). Even when both are investigating the same party, the items they examine and the sources they consult differ, so the crucial thing is never to let one side's result stand in for the other.

The verifications the export control team must nail down fall broadly into four. First, screening the counterparty against sanctions lists. Not just Japan's Foreign End User List, but the U.S. BIS Entity List, the U.S. Treasury OFAC SDN List, and others — checked across multiple lists. That is because a transaction involving U.S.-origin parts or technology can run afoul of U.S. reexport controls even when it clears Japanese law. Second, identifying the ultimate beneficial owner (UBO): tracing who truly controls the counterparty behind the party visible on the surface. Third, confirming the party is not a military-linked end user. Fourth, verifying the end use and the end user — the so-called end-user check.

None of these four is a "do it once and you're done" task. Sanctions lists are updated frequently, and the Foreign End User List is revised on an ongoing basis. Even if there is no problem when the relationship begins, a counterparty can become sanctioned partway through. That is exactly why you need a practice of re-screening against the latest lists at each transaction and on a regular cadence. Where this is done by hand, the burden on the person in charge is heavy and keeping up with updates tends to lag.

To lighten this screening burden, we provide the AI export control agent TRAFEED. TRAFEED complies with METI standards and, while reflecting updates to each country's regulations and lists on the same day, makes a counterparty's level of concern visible. It is designed to support the parts that are hard to keep up with by hand — cross-referencing sanctions lists, mapping capital relationships, and the like. That said, it does not take over the judgment. Given how the export control regime is built, the final classification and the decision on whether to proceed with a transaction rest with your company's export control officer. The tool's role is confined to assembling the material so that the officer can decide correctly and quickly. Leave credit to the credit management team and credit agencies, and export control to the export control team and tools like this — each to the right hands. The more a company gets this division right, the less likely it is that screening gaps appear.

Summary

When we order a credit report and check the rating, we feel a sense of accomplishment at having "investigated the counterparty." That feeling is where the export control blind spot lives. A financial credit check answers only "can they pay?"; it says nothing at all about "will this break the law?"

Finally, here are three checkpoints you can use starting tomorrow. One: are you making export-control go/no-go decisions based on a credit rating? Two: rather than stopping at classification, are you running end-user and end-use verification through to the end? Three: are you updating your sanctions-list and UBO screening both at each transaction and on a regular cadence? If these three run as internal procedures, you can largely prevent the "credit approved, then FEFTA violation" accident.

If you are worried that your counterparty screening leans too heavily toward financial credit, use the export compliance check to confirm where you stand. And if you want to discuss a screening framework tailored more specifically to your own trade flows and counterparties, we can talk it through in terms grounded in export control practice via a TRAFEED consultation. Financial soundness and legal safety are two things to be confirmed separately. Whether you can hold them apart in your thinking is what divides export compliance from the rest.


References

Footnotes

  1. Credit Investigation (Corporate Credit Checks) — Teikoku Databank, Ltd. (Japanese)

  2. Foreign Exchange and Foreign Trade Act (FEFTA, Act No. 228 of 1949) — e-Gov Law Search (Japanese)

  3. How to Confirm Classification for Exports: Japan — JETRO Trade and Investment Q&A (Japanese)

  4. Basics of Export Control — Center for Information on Security Trade Control (CISTEC) (Japanese)

  5. Export Trade Control Order (Cabinet Order No. 378 of 1949, Item 16 of Appended Table 1) — e-Gov Law Search (Japanese)

  6. Supplementary Export Controls (Catch-All Controls) — Ministry of Economy, Trade and Industry (Japanese)

  7. Catch-All Controls under Security Trade Control: Japan — JETRO Trade and Investment Q&A (Japanese)

  8. On the Review of Supplementary Export Controls (effective October 9, 2025) — Ministry of Economy, Trade and Industry (Japanese)

  9. Ordinance Establishing Compliance Standards for Exporters (METI Ordinance No. 60 of 2009) — e-Gov Law Search (Japanese)

  10. Revision of the Foreign End User List (September 29, 2025) — METI Press Release (Japanese) 2

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

シェア

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

無料診断ツール

輸出管理のリスク、見えていますか?

まず5問(約2分・メール不要)のライト診断。必要なら10問本編で詳細レポートまで。

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles